<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cert profile and SAML to Azure with GP Gateway Machine Cert Possible? in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/cert-profile-and-saml-to-azure-with-gp-gateway-machine-cert/m-p/334378#M223</link>
    <description>&lt;P&gt;Is it possible to use a Certificate Profile to verify a machine on your GP Gateway, all while using SAML authentication to Azure?&amp;nbsp; SAML to our Azure instance works great for us now, but does the firewall use the certificate profile only as a 'pre-logon' user, or initial challenge, and then still send the user to azure to complete SAML authentication?&amp;nbsp; &amp;nbsp; &amp;nbsp;Considering using certificates to verify machines, but still want to use SAML.&amp;nbsp; &amp;nbsp;We have Azure joined machines and thinking they have a certificate on them somewhere with a CA we could utilize. Looking to Add device authentication from an Azure joined/trusted machine, and still use SAML for users.&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 19 Jun 2020 19:58:37 GMT</pubDate>
    <dc:creator>Sec101</dc:creator>
    <dc:date>2020-06-19T19:58:37Z</dc:date>
    <item>
      <title>Cert profile and SAML to Azure with GP Gateway Machine Cert Possible?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/cert-profile-and-saml-to-azure-with-gp-gateway-machine-cert/m-p/334378#M223</link>
      <description>&lt;P&gt;Is it possible to use a Certificate Profile to verify a machine on your GP Gateway, all while using SAML authentication to Azure?&amp;nbsp; SAML to our Azure instance works great for us now, but does the firewall use the certificate profile only as a 'pre-logon' user, or initial challenge, and then still send the user to azure to complete SAML authentication?&amp;nbsp; &amp;nbsp; &amp;nbsp;Considering using certificates to verify machines, but still want to use SAML.&amp;nbsp; &amp;nbsp;We have Azure joined machines and thinking they have a certificate on them somewhere with a CA we could utilize. Looking to Add device authentication from an Azure joined/trusted machine, and still use SAML for users.&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jun 2020 19:58:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/cert-profile-and-saml-to-azure-with-gp-gateway-machine-cert/m-p/334378#M223</guid>
      <dc:creator>Sec101</dc:creator>
      <dc:date>2020-06-19T19:58:37Z</dc:date>
    </item>
    <item>
      <title>Re: Cert profile and SAML to Azure with GP Gateway Machine Cert Possible?</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/cert-profile-and-saml-to-azure-with-gp-gateway-machine-cert/m-p/335405#M240</link>
      <description>&lt;P&gt;Yes, this is perfectly possible.&amp;nbsp; We do this w/ our SAML authentication.&amp;nbsp; If you add a certificate profile under your-GP-portal (or gateway) &amp;gt; Authentication &amp;gt; Certificate Profile, any client that connects to that portal/gateway will need a cert signed by that CA.&amp;nbsp; You can still use SAML authentication for the user.&amp;nbsp; From the documentation:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;DIV class="Table_Cell"&gt;Certificate Profile&lt;/DIV&gt;&lt;/TD&gt;&lt;TD&gt;&lt;DIV class="Table_Cell"&gt;(&lt;SPAN class="Teletype"&gt;Optional&lt;/SPAN&gt;) Select the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="uicontrol"&gt;Certificate Profile&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;the gateway uses to match those client certificates that come from user endpoints. With a Certificate Profile, the gateway authenticates the user only if the certificate from the client matches this profile.&lt;/DIV&gt;&lt;DIV class="Table_Cell"&gt;If you set the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="uicontrol"&gt;Allow Authentication with User Credentials OR Client Certificate&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;option to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="uicontrol"&gt;No&lt;/SPAN&gt;, you must select a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="uicontrol"&gt;Certificate Profile&lt;/SPAN&gt;. If you set the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="uicontrol"&gt;Allow Authentication with User Credentials OR Client Certificate&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;option to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="uicontrol"&gt;Yes&lt;/SPAN&gt;, the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="uicontrol"&gt;Certificate Profile&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is optional.&lt;/DIV&gt;&lt;DIV class="Table_Cell"&gt;The certificate profile is independent of the OS.&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2020 18:47:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/cert-profile-and-saml-to-azure-with-gp-gateway-machine-cert/m-p/335405#M240</guid>
      <dc:creator>OwenFuller</dc:creator>
      <dc:date>2020-06-25T18:47:48Z</dc:date>
    </item>
  </channel>
</rss>

